Courseiva

Cybersecurity-Apprentice · domain

Cloud Security

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Cloud Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

26 questions7 easy10 medium9 hard

Focused practice

Practice Cloud Security questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Cloud Security

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Question index

All Cloud Security questions (26)

Click any question to see the full explanation, or start a practice session above.

1

A security operations team is investigating an incident where an attacker compromised cloud credentials and attempted privilege escalation. Which THREE Prisma Cloud features or data sources assist in detecting and investigating this cloud security incident? (Choose three)

Hard
2

Under the shared responsibility model in cloud computing, the customer retains responsibility for securing specific layers regardless of whether the service is IaaS, PaaS, or SaaS. Which TWO items are always the customer's responsibility? (Choose two)

Easy
3

An administrator needs to restrict access to the Prisma Cloud administrative console based on corporate IP ranges. Where within the Prisma Cloud platform should the administrator configure trusted IP address restrictions?

Medium
4

A junior cloud engineer is configuring a new AWS S3 bucket and wants to ensure that Prisma Cloud successfully detects public exposure risks. Which Prisma Cloud feature continuously evaluates cloud resource configurations against security benchmarks like CIS?

Easy
5

A security architect is designing an enterprise logging strategy where all Prisma Cloud audit alerts, vulnerability findings, and compliance violations must be streamed to a third-party SIEM (such as Splunk). Which Prisma Cloud feature should be configured to achieve real-time log export?

Hard
6

A security administrator is evaluating cloud environments and needs to determine where customer responsibility ends in an Infrastructure as Service (IaaS) model. Which component is managed entirely by the cloud provider in IaaS?

Easy
7

A security engineer is configuring Prisma Cloud Compute runtime defense rules for containerized workloads. Which THREE runtime behaviors can Prisma Cloud Compute monitor and defend against? (Choose three)

Medium
8

An enterprise security architect is reviewing Prisma Cloud integration options for securing cloud-native applications throughout their lifecycle. Which THREE activities are supported by Prisma Cloud Application Security (IaC Security)? (Choose three)

Hard
9

An application security engineer configures Prisma Cloud WAAS (Web Application and API Security) to protect a containerized microservices application running behind an ingress controller. Which deployment method is supported for WAAS in a Kubernetes environment?

Hard
10

An administrator is reviewing the core components and capabilities of Prisma Cloud Cloud Security Posture Management (CSPM). Which TWO capabilities are primary functions of Prisma Cloud CSPM? (Choose two)

Easy
11

An administrator is deploying Prisma Cloud to secure a multi-cloud environment consisting of AWS and Azure. The administrator needs to understand the boundaries of security management under the shared responsibility model. Which responsibility always remains with the customer regardless of the cloud service model used?

Easy
12

A DevOps engineer observes that Prisma Cloud Compute vulnerability scans are reporting high severity Common Vulnerabilities and Exposures (CVEs) on running containers, but the build pipeline failed to catch them. How should the engineer integrate Prisma Cloud into the CI/CD pipeline to prevent vulnerable images from being built and pushed?

Hard
13

An auditor requests evidence that public AWS S3 buckets are automatically remediated when discovered by Prisma Cloud. Which feature should the security engineer configure to achieve automated remediation?

Medium
14

An enterprise security team wants to prevent developers from deploying Infrastructure as Code (IaC) templates that contain misconfigurations, such as open security groups. Which Prisma Cloud module should be integrated into the developer workflow (e.g., GitHub or Terraform Cloud)?

Medium
15

An enterprise security team deploys Prisma Cloud Compute across their Kubernetes clusters to enforce security policies. A developer attempts to deploy a privileged pod that violates runtime security policies. Which Prisma Cloud component intercepts and blocks this deployment at the admission controller level?

Medium
16

A security analyst receives a Prisma Cloud alert regarding suspicious API activity in an AWS account, indicating potential credential compromise. Which Prisma Cloud module generated this alert by analyzing cloud provider audit logs for anomalous behavior?

Medium
17

A security architect is configuring CloudTrail integration for Prisma Cloud across multiple AWS accounts managed through AWS Organizations. Which account deployment method should be used to ensure centralized log ingestion and security posture visibility?

Medium
18

An administrator is configuring Prisma Cloud Compute defense mechanisms for serverless functions (FaaS) such as AWS Lambda. Which THREE capabilities does Prisma Cloud provide for serverless security? (Choose three)

Hard
19

An administrator is reviewing Prisma Cloud agentless scanning capabilities for AWS EC2 instances. What is the primary advantage of utilizing agentless scanning compared to deploying the traditional Defender agent on every workload?

Medium
20

An auditor notices that a cloud account onboarded to Prisma Cloud has generated numerous alerts for unused IAM access keys. Which underlying Prisma Cloud data source is evaluated to detect this condition?

Hard
21

A compliance officer needs to verify whether cloud storage buckets across AWS and Azure meet corporate encryption standards. Which Prisma Cloud module provides out-of-the-box compliance reporting against standards such as HIPAA and PCI-DSS?

Easy
22

A security analyst is reviewing compliance posture using Prisma Cloud Compute and needs to secure cloud workloads. According to the shared responsibility model for a containerized application running on AWS Elastic Kubernetes Service (EKS), who is responsible for patching the container OS base image?

Easy
23

A security engineer is writing a custom RQL (Resource Query Language) search in Prisma Cloud to find all AWS EC2 instances that do not have encryption enabled on their root volumes. Which RQL query syntax is correct?

Medium
24

An enterprise has strict compliance requirements requiring visibility into network traffic flows between Kubernetes pods across different namespaces. Which Prisma Cloud Compute feature should be enabled to monitor and enforce layer 7 network segmentation rules inside the cluster?

Hard
25

When onboarding multi-account cloud environments into Prisma Cloud, administrators can choose from several integration methods. Which THREE advantages are gained by setting up centralized cloud account onboarding and role aggregation? (Choose three)

Medium
26

An administrator needs to onboard a new Google Cloud Platform (GCP) organization into Prisma Cloud with least-privilege permissions. Which GCP authentication method does Prisma Cloud recommend and support for secure API integration?

Hard

Frequently asked questions

What does the Cloud Security domain cover on the Cybersecurity-Apprentice exam?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How many questions are in this domain?
This page lists all 26 Cloud Security questions in the Cybersecurity-Apprentice question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-cybersec-apprentice PANW-CYBERSEC-APPRENTICE cloud security Practice Questions